image-upscaling

Fail

Audited by Socket on Feb 25, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This package is documentation for a cloud-hosted image upscaling workflow that depends on installing and running the infsh CLI and invoking remote inference.sh apps. The primary security concerns are the recommended pipe-to-shell installation method (remote code executed locally) and the fact that images and authentication credentials are handled by external hosted services (data leaves the user's environment). There is no direct evidence in the provided text of obfuscated or intentionally malicious code, hard-coded credentials, covert exfiltration to unknown domains, or backdoors. However, the supply-chain and privacy risks are non-trivial and warrant caution: prefer manual install with checksum verification, review credential storage practices, and avoid uploading sensitive images to the service if confidentiality is required.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 25, 2026, 05:38 PM
Package URL
pkg:socket/skills-sh/inference-sh-9%2Fskills%2Fimage-upscaling%2F@7a1895a7127347e1d5f535739db50f807f9c5c0e